1. headers http header: x-content-type-options